Betterleaks Cloud - GitHub, Git, S3, Dir Secret Scanner
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
Cloud-hosted Betterleaks v1.3.1 for hunting leaked API keys, wallet private keys, and credentials anywhere on GitHub, in cloned git repos, or in S3 / R2 / MinIO buckets. Optional live validation probes each detected secret against the vendor API to flag which ones are still active.
Available as an Apify Actor. $0.05 start + $0.05 per repo scanned + $0.30 per live-validated key. No install, no CLI, flat JSON output.
Scans a GitHub org, user, repo, pull request, issue, gist, action workflow, or S3 bucket for leaked credentials. Built on Betterleaks (the Gitleaks successor, maintained by the original Gitleaks author Zachary Rice + co-maintainers from Red Hat, Amazon, RBC). Every Betterleaks CLI flag is exposed as an input field. When you enable validation, each finding is probed live against the vendor API and tagged valid, invalid, revoked, unknown, or error.
| Local Betterleaks CLI | This actor | |
|---|---|---|
| Setup | Install Go binary, set up GitHub token, configure shell | Paste a JSON input |
| Scope | One target at a time | github / git / s3 modes + our global_github mode (Code Search picks repos) |
| Validation cost | Your machine's HTTP egress | Apify-managed, parallel workers |
| Output handling | stdout JSON, parse yourself | Dataset records, filterable views |
| Schedule | cron + DIY | Apify Schedules built-in |
| Cost | Your laptop's electricity | $0.05 actor start + $0.05 per repo scanned |
| gitleaks-cloud | betterleaks-cloud (this) | |
|---|---|---|
| Engine | Gitleaks 8.x | Betterleaks 1.3.1 (Gitleaks successor) |
| Live validation | not supported | yes (opt-in) |
| Source types | github + git only | github, git, s3, dir, stdin, global_github |
| Pricing | $0.01 + $0.02 per repo | $0.05 + $0.05 per repo + $0.30 per live-validated key |
| Best for | Volume scanning, low cost per scan | Premium scans where "is the secret still live?" matters |
Pay-per-event:
valid)global_github mode)Typical scans:
| Scenario | Cost |
|---|---|
| Scan 1 small repo, 1 finding, no validation | $0.11 |
| Scan 1 big repo, 30 findings, no validation | $0.40 |
| Scan an org with 25 repos, 50 findings, no validation | $1.80 |
25-repo global search for rzp_live_ | $1.93 |
| 100-repo scan, 200 findings, 10 live-validated | $10.05 |
Compare to GitGuardian Enterprise at ~$5000/year flat. Per-comprehensive-scan with this actor is 300-500x cheaper.
| Mode | What it scans | Required input |
|---|---|---|
github | A specific GitHub org / user / repo / PR / issue / gist (you choose) | target_url, github_token recommended |
global_github | All of GitHub by keyword - we add this layer via Code Search | global_search_query, github_token required |
git | A single git clone URL with full history | target_url |
s3 | AWS S3, Cloudflare R2, MinIO, or any S3-compatible bucket | target_url, S3 creds (or s3_anonymous for public) |
dir | A tarball / zip URL - we download, extract, scan filesystem | dir_source_url |
stdin | Raw text content you paste in | stdin_content |
github mode?All 12 surfaces betterleaks supports, selectable via include / exclude:
repos (default), forksprs, pr-commentsissues, issue-commentsactions, action-artifactsdiscussionsreleases, release-assetsgistsYou can also filter by since / until dates, exclude repos by glob pattern, or target specific GitHub Actions workflow files.
Yes. Betterleaks scans the full git history. A secret that was committed and then deleted in a later commit still appears in the history and gets detected. The Commit field on each finding tells you which commit introduced the leak.
You can also enable advanced --log-opts pass-through to use git pickaxe (-S secret_string) for targeted historical searches.
Optional - off by default to keep scans fast. Set validation: true and Betterleaks fires HTTP requests against the vendor API for each finding using the rule's built-in CEL validator.
Output fields:
ValidationStatus: valid (still active), invalid (rejected), revoked (explicitly disabled), unknown (couldn't determine), or errorValidationReason: human-readable whyValidationMeta: vendor-specific metadata. For a GitHub PAT, this includes username, name, and granted scopes. For Stripe, the test/live mode + account info.Note: validation only fires for rules that ship with a validate CEL clause in their TOML. Not every detected secret type has one (the upstream rule set is expanding over time).
You can also tune validation behavior:
validation_timeout (per-request HTTP timeout)validation_workers (parallel HTTP workers)validation_status (filter output to only certain statuses)validation_debug (include raw HTTP response in ValidationMeta)validation_extract_empty (include validator outputs even when empty)validation_env_vars (expose extra env vars to CEL validators)Yes - paste a full betterleaks TOML config into custom_config_toml. Either replaces the built-in rules or adds to them depending on how you write the TOML.
You can also use enable_rule to run only a whitelist of rule IDs (e.g. ["github-fine-grained-pat", "stripe-secret-key"]) from the built-in set without writing your own config.
Reference format: https://github.com/betterleaks/betterleaks/blob/main/.betterleaks.toml
Each dataset record is the raw Finding struct from betterleaks - no transformation, no field renaming:
The dataset has two pre-configured views:
ValidationStatus == valid, the high-signal triage listBased on the underlying Betterleaks 1.3.1 rule set (200+ detectors), plus the upstream's BPE-tokenization based false-positive filter and CEL-based contextual filters. Compute usage observed in real test runs:
anshumanatrey/* (~30 repos): ~134 seconds, 0.1491 compute units, 735 findingsglobal_github scan with query rzp_live_: ~8.5 seconds, 0.0095 compute units, 14 findingsQ: Can I scan a private repo? Yes - provide a github_token with repo scope.
Q: Does it scan PR branches and dangling commits? PR refs yes via --include prs. Dangling commits aren't currently exposed but the underlying tool supports it.
Q: How does it handle rate limits? Without a github_token, GitHub limits to ~60 req/hr shared. With a token: 5000 req/hr on your account. Always provide a token for any real scan.
Q: Can I run it on a schedule? Yes via Apify Schedules. Recommended for continuous monitoring use cases.
Q: Can I use my own betterleaks rule TOML? Yes via custom_config_toml. Or whitelist specific built-in rules via enable_rule.
Q: What's global_github mode? Our addition on top of upstream betterleaks. You provide a search query, we use GitHub Code Search to find unique candidate repos, then run betterleaks git against each in parallel. Useful for hunting a specific secret pattern across all of GitHub.
Q: Why not use the cheaper gitleaks-github-secret-scanner actor instead? Use that one for high-volume cost-sensitive scans. Use this one when live validation matters (bug bounty triage, incident response, knowing which secrets to actually rotate).
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/betterleaks-cloud-github-git-s3-dir-secret-scanner)<a href="https://allmcps.com/mcp/betterleaks-cloud-github-git-s3-dir-secret-scanner"><img src="https://allmcps.com/api/badge/betterleaks-cloud-github-git-s3-dir-secret-scanner?style=directory" alt="Betterleaks Cloud GitHub, Git, S3, Dir Secret Scanner on AllMCPs" /></a>